Google Expands Linux Kernel Vulnerability Incentive Program

Google announced the expansion of the initiative to pay cash rewards for identifying vulnerabilities in the Linux kernel. The maximum payout for a new vulnerability and the creation of a working exploit based on it has been increased from $91 to $133. In addition to the previously used kCTF (Kubernetes Capture the Flag) environment, new environments have been proposed for hacking attempts: based on the latest stable branch of the regular Linux kernel and based on the kernel branch, which includes additional patches to block typical exploit methods.

An additional reward of $21 is paid for creating exploits that hit the environment with a fresh stable kernel branch. An additional $21 could be paid for hacking an environment with advanced security measures. It is noted that the proposed advanced protection measures are able to block 9 out of 10 vulnerabilities received last year and 10 out of 13 exploits claiming rewards.

Source: opennet.ru

Add a comment